CVE-2025-57788: Unauthorized API Access Risk
Published Aug 20, 2025
·Updated
A vulnerability in a known login mechanism allows unauthenticated attackers to execute API calls without requiring user credentials. RBAC helps limit the exposure but does not eliminate risk.
Affected Software
2 affected components
Commvault Commvault<11.36.60
Commvault Commvault<11.36.60
Event History
Aug 20, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Data Sourced
via NVD·04:16 AM
DescriptionSeverityWeaknessAffected Software
News Published
via The Register·05:03 PM
News Published
via The Register·05:07 PM
Frequently Asked Questions
1
What is the severity of CVE-2025-57788?
CVE-2025-57788 is rated as a high-severity vulnerability due to its potential for unauthorized API access.
2
How do I fix CVE-2025-57788?
To fix CVE-2025-57788, upgrade to Commvault version 11.36.60 or later.
3
What kind of attacks can CVE-2025-57788 enable?
CVE-2025-57788 allows unauthenticated attackers to execute API calls, which could lead to unauthorized data access or manipulation.
4
Is my system vulnerable to CVE-2025-57788?
If you are using Commvault version earlier than 11.36.60, your system is vulnerable to CVE-2025-57788.
5
What is the impact of CVE-2025-57788?
The impact of CVE-2025-57788 includes unauthorized access to sensitive data and potential disruption of services due to uncontrolled API access.